Skip to content
Security and Trust

Your account.
Your data.
Your control.

Two-factor authentication, scoped API keys, SSH keys for SFTP, and a one-click GDPR data export. The basics done properly, built into every account.

We process data subject to UK GDPR and the Data Protection Act 2018. Your server data is hosted at Hetzner Falkenstein (ISO 27001).

UK-based team

GDPR-compliant handling

ISO 27001 DC

Hetzner Falkenstein

UK GDPR

Data Protection Act 2018

No data sold

to any third party

Account security

What every account includes.

Security features are not add-ons. They are built into every plan.

Two-factor authentication

Protect your account with a TOTP authenticator app (Google Authenticator, Authy, or any RFC 6238-compatible app). Recovery codes are generated at setup and can be regenerated at any time.

  • TOTP (Time-based One-Time Password)
  • Recovery codes for account access without a device
  • Enforced on panel login - no bypass

Scoped API keys

Generate API keys with specific permission scopes from your account settings. Use them to automate server management without exposing your full account credentials.

  • One key per integration - not one key for everything
  • Revoke keys individually at any time
  • Keys shown once at creation - stored hashed

SSH keys for SFTP

Add your public SSH key to the panel and use it for SFTP access. No password required over the wire. Keys can be revoked without changing your account password.

  • Add multiple keys for different devices
  • SFTP access only - not shell access
  • Revoke any key from the panel

GDPR data export

Request a copy of everything we hold on your account in one click. The export includes your account details, server configurations, and activity history in a structured format.

  • One-click export from account settings
  • Includes all server configs and account data
  • Delivered as a downloadable archive

Activity log

Every action against your servers is logged: file changes, restarts, permission changes, subuser additions, and more. The log shows who did what and when.

  • Per-server audit trail
  • Actions attributed to account or subuser
  • Useful for teams with multiple admins

UK-based hosting

Your servers and data are hosted in Germany (Hetzner Falkenstein, DE) with our team and company based in the UK. We are subject to UK GDPR and the Data Protection Act 2018.

  • Hetzner data centre (ISO 27001 certified)
  • Subject to UK GDPR and Data Protection Act 2018
  • No data sold to third parties

GDPR rights

Data export and deletion

Under UK GDPR you have the right to access, correct, and delete the personal data we hold. You can exercise all of these rights directly from your account settings without contacting support.

If you need to raise a data protection complaint, our process is documented and ICO escalation instructions are provided if we cannot resolve it directly.

Right of access

One-click data export from Account Settings

Right to rectification

Edit account details directly from Account Settings

Right to erasure

Account deletion from Account Settings. Data removed within 30 days.

Right to data portability

Data export delivered as a structured, machine-readable archive

Right to object

Marketing opt-out from account settings. No profiling for advertising.

Teams and subusers

Grant access without sharing your account.

Add team members as subusers with granular permissions. Each subuser has their own login. You choose exactly what they can see and do. Revoke access at any time without affecting anyone else.

Granular permissions

Permissions are split into 8 categories: console, files, backups, databases, schedules, startup, settings, and users. Grant only what each person needs.

All actions logged

Every action by a subuser appears in the server activity log attributed to their account. You always know who did what.

Instant revocation

Remove a subuser's access from the panel at any time. Their session ends immediately. No need to change passwords or rotate credentials.

FAQ

Common questions

Does Zeros Host support two-factor authentication?

Yes. TOTP-based two-factor authentication is available on all accounts. You can add a TOTP authenticator app and generate recovery codes from your account security settings.

Can I generate API keys to automate server management?

Yes. You can create scoped API keys from your account settings. Each key has specific permissions and can be revoked individually at any time.

Where is my data stored?

Server data is hosted in a Hetzner data centre in Falkenstein, Germany. We process data subject to UK GDPR and the Data Protection Act 2018.

How do I export my data?

You can request a data export from your account settings at any time. The export includes your account details, server configurations, and activity history.

How do I delete my account?

Account deletion is available from your account settings. All servers and data associated with the account are removed within 30 days of deletion.

Get started

Ready to try it?

24 hours free. No card required. All security features included on every plan.

Start free trial

Questions? Get in touch or read our Privacy Policy.